Comment on Is Authelia enough without fail2ban or crowdsec?

<- View Parent
IanTwenty@piefed.social ⁨2⁩ ⁨weeks⁩ ago

Say that new authelia exploit looks like one fail2ban already recognises or relies on timing/brute-force then you’re covered even before a patch is available.

Here’s a real authelia vuln:

https://app.opencve.io/cve/CVE-2026-47203

allowing an attacker to circumvent login throttling or account lockouts by simply altering the case of their credentials.

I think fail2ban would help protect authelia here?

original
Sort:hotnewtop